← Back to browse · API

CVE-2026-40372

Severity
CRITICAL
CVSS
9.1
EPSS
0.11205
Risk score
40.32
CISA KEV
No
PoC
No
Published
2026-04-21
Modified
2026-08-14
First seen
2026-08-07
Aliases
EUVD-2026-24249, GHSA-9MV3-2CWR-P262
Products
Microsoft:ASP.NET Core 10.0 10.0 <10.0.7, Microsoft:Microsoft Visual Studio 2026 version 18.5 18.5.0 <18.5.2
Sources
euvd EUVD-2026-24249

Description

Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.

References